Cross-site Scripting Vulnerability in Themeum WP Crowdfunding Plugin
CVE-2025-31892

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
1 April 2025

What is CVE-2025-31892?

The Themeum WP Crowdfunding plugin is vulnerable to a Cross-site Scripting (XSS) issue that arises from improper neutralization of input during web page generation. This vulnerability allows for the potential storage and execution of malicious scripts within the context of the user’s session, exposing users to attacks when they interact with affected content. The vulnerability impacts versions of WP Crowdfunding from n/a up to 2.1.13, emphasizing the importance of updating to safeguard against potential exploits.

Affected Version(s)

WP Crowdfunding <= 2.1.13

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

theviper17 (Patchstack Alliance)
.